Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
An Ontario mortgage brokerage and an Ontario insurance brokerage sit inside the same incident-notification regime. FSRA supervises both. It has adopted the Mortgage Broker Regulators’ Council of Canada cybersecurity guidance for the mortgage side, and RIBO issued Responsible AI Use guidance in May 2025.
FINTRAC reporting stacks on top, and PIPEDA sits above it. This is the playbook I run with 6 to 25-agent Ontario brokerages in 2026: the spine matrix, the notification SOP, lender-channel hardening, and my 90-day rollout.
One correction first, because I keep finding it in Ontario brokerage policy binders. The MBRCC guidance contains 4 principles, not 9. Nine is the control count my decomposition produces. Only one of those numbers is the regulator’s.
Key Takeaways
- FSRA’s IT Risk Management Guidance (GR0016INT, effective April 1, 2024) binds every FSRA-regulated entity across seven practices. Practice 7 asks for notification normally within 72 hours, after the entity finds an incident material.
- The MBRCC Principles for Cybersecurity Preparedness set four outcome-based principles: responsibility and resourcing, identification and prevention of risks, incident monitoring and response, and third-party management.
- That document carries a 22-question self-assessment checklist, and MBRCC says regulators may use it during routine monitoring. I treat it as Ontario’s closest thing to a published exam script.
- RIBO’s Responsible AI Use Among RIBO Licensees guidance (May 29, 2025) imposes four governance pillars on insurance brokerages using AI. It never reaches a mortgage brokerage.
- A 12-agent brokerage on Microsoft 365 Business Premium lands near CA$32 per user per month, plus 24 to 32 hours of configuration. Runbook discipline, rather than licensing spend, produces the defensible posture.
The 2026 FSRA stack: why both mortgage and insurance brokerages are in the same incident regime
FSRA is the market-conduct regulator for both sectors, stood up in 2019 as the successor to FSCO. It delegates insurance-broker licensing to RIBO and has adopted the MBRCC principles.
The Ontario reality is simple. A mortgage brokerage holds borrower SIN and T4 income statements plus lender-channel credentials. An insurance brokerage holds policyholder PII and beneficiary data. The control set is the same. The paperwork on top is the differentiator.
MBRCC’s four cybersecurity principles, explained: what each one requires
I read the source rather than the summaries, because the summaries are where the nine-principle myth starts. The MBRCC Principles for Cybersecurity Preparedness is a five-page PDF: four numbered principles, a self-assessment checklist, and a standards list citing ISO/IEC 27001 and OSFI.
Principle 1, responsibility and resourcing. Appoint a named person accountable for cybersecurity risk, keep their skills current and raise staff awareness. Consider cyber-liability insurance. In a 12-agent brokerage that is the principal broker or broker-of-record.
Principle 2, identification and prevention of risks. Identify risks across staff access, third-party providers and technical safeguards. Keep endpoint protection current, run a business-impact assessment and state a risk tolerance.
Principle 3, incident monitoring, detection and response. Hold a documented protocol covering suspension of business processes, information-sharing with clients and lenders, return-to-normal criteria, and data restoration.
Principle 4, third-party management. Take reasonable steps to confirm external providers also hold preparedness practices across the application-to-closing chain. A larger provider network raises the risk.
My nine-control decomposition of those four principles sits in the annotated MBRCC principles guide for Ontario mortgage brokerages. The principles sit at governance level, so the decomposition is the working layer above a Microsoft 365 tenant.
Not sure where your MBRCC gaps are? Book a review with Mike Pearlstein, CISSP →
RIBO’s May 2025 Responsible AI Use: the 4 governance pillars insurance brokerages must satisfy
RIBO published Responsible AI Use Among RIBO Licensees on May 29, 2025. It reaches every Ontario-licensed insurance broker using generative or predictive AI inside licensed activities. The four pillars frame the obligations. The controls that satisfy them are ordinary IT work.
Pillar 1, competency and accountability. The licensee stays responsible for whatever the tool produces. The control is an approval workflow, with a named licensed reviewer signing off before anything leaves.
Pillar 2, client interest and suitability. A licensed member oversees AI-generated content before a client sees it: no auto-send on AI-drafted email, and a record of who approved what.
Pillar 3, transparency and human oversight. Clients should know when they are engaging with AI. The control is a disclosure in the privacy notice, plus labelling on AI-assisted correspondence.
Pillar 4, privacy and data protection. The brokerage vets its AI vendors so policyholder data neither leaves its control nor feeds model training. We deploy a four-question checklist: where is data processed, what is the residency commitment, is it used for training, and how is it deleted on exit.
“Anything generated or altered by an AI tool is overseen by a licensed member before being presented to a client.”
Registered Insurance Brokers of Ontario, Responsible AI Use Among RIBO Licensees, May 29, 2025.
FSRA IT Risk Incident Notification: the 15-minute SOP that applies to both verticals
Read the trigger carefully. The 72-hour clock starts when the brokerage determines the incident is material, not when a technician first sees an alert. What FSRA examines is how long that determination took, and whether the reasoning was written down.
That is why I run a 15-minute triage clock in front of the 72-hour one. Triage inside 15 minutes, then a written materiality call, then the notification. Treat the two as one clock and you file late.
Six steps run the same on both sides. Detection raises an alert. The IT lead triages inside 15 minutes. The principal broker records the materiality call. The form goes to FSRA. The compliance officer opens the FINTRAC branch. The privacy lead applies the PIPEDA harm test.
The form wants 5 things: entity name and licensing reference, detection date and time, systems and data classes affected, containment steps taken, and a lead contact. Root-cause analysis is not required yet.
The Spine Matrix: FSRA / MBRCC / RIBO requirements x brokerage type x Microsoft 365 Business Premium controls
This is my week 1 handout. Each row carries the obligation, the vertical it binds, the Microsoft 365 Business Premium control that satisfies it and the artifact that proves it at an FSRA examination. That last column is the one brokerages miss first time.
| Requirement | Source | Applies to | M365 Business Premium control | Evidence kept |
|---|---|---|---|---|
| Named accountable person for IT risk | MBRCC P1; GR0016INT | Both | Governance charter naming the PB or BOR | Signed charter, quarterly minutes. |
| Documented risk assessment | MBRCC P2; GR0016INT | Both | Annual IT risk register | Register PDF, dated and signed. |
| MFA on every client-data account | MBRCC P2; GR0016INT | Both | Entra ID conditional access | Policy export, 90-day sign-in logs. |
| Role-based access on the BMS | MBRCC P2 and P4 | Both | Filogix, Applied Epic, Vertafore roles | Admin export, quarterly review log. |
| Endpoint and email threat protection | MBRCC P2; GR0016INT | Both | Defender for Business; Defender for Office 365 P1 | Monthly device health, quarterly quarantine report. |
| Incident notification SOP | MBRCC P3; Practice 7 | Both | Written 6-step runbook; annual tabletop | Runbook PDF, after-action report. |
| Backup and recovery with RPO and RTO | MBRCC Appendix A | Both | Third-party Microsoft 365 backup platform | Quarterly restore-test log. |
| Third-party and vendor risk review | MBRCC P4; RIBO pillar 4 | Both | Checklist: residency, training, deletion | Signed vendor reviews on file. |
| AI review workflow and client disclosure | RIBO pillars 1, 2, 3 | Insurance | Copilot governance; published AI-use policy | Approval log, dated policy. |
| FINTRAC reporting capacity | PCMLTFA | Mortgage and life | Portal access; named compliance officer | Annual compliance-regime review. |
Canadian data sovereignty: borrower SIN, T4s, policyholder PII, claims history
Both classes attract US CLOUD Act exposure on American infrastructure, Law 25 obligations on a Quebec file and PIPEDA everywhere else.
The residency play is to provision the Microsoft 365 tenant in the Canada region, so Exchange, SharePoint, OneDrive and Teams data stores in Canada Central and Canada East. That does not erase CLOUD Act exposure, because Microsoft Corporation is a US-incorporated parent. I say so to every brokerage that asks.
For Quebec policyholders, Law 25 adds a privacy impact assessment before information moves outside Quebec, a designated privacy officer and notification to the Commission d’accès à l’information. One file brings it into scope.
For the wider financial-sector bar, the OSFI Technology and Cyber Risk Management guideline is the frame underwriters expect mirrored at the brokerage layer. MBRCC cites it in Appendix B.
Lender-channel hardening for mortgage brokerages: Filogix, Velocity, BluMortgage, Finmo, Newton
MBRCC Principle 2 reaches staff access and Principle 4 reaches third-party providers. Between them they cover every platform touching borrower data: Filogix Expert, Velocity, BluMortgage, Finmo and Newton by Lendesk. Each carries its own credential model, its own role model, and its own MFA switch.
Step 1: enable MFA at the platform level, not only at the Microsoft 365 layer. Step 2: set role-based permissions so junior agents see only their own files. Step 3: rotate lender-channel credentials quarterly. Step 4: retain 12 months of audit logs. Step 5: deactivate the BMS account before the Microsoft 365 account.
That last step matters more than it sounds. An ex-agent whose email was cut off can still pull live borrower SIN data if the broker management system account survived. Cloud platforms inherit SOC 2 controls, but account lifecycle stays yours.
My full sequence sits in the Filogix and Velocity account-hardening guide. Mortgage Professionals Canada publishes member guidance tracking the same principles.
Insurance broker IT hardening: Applied Epic, Vertafore, EZLynx, Power Broker
An Ontario insurance brokerage usually sits on Applied Epic, Vertafore, EZLynx or Power Broker. Each holds policyholder PII, claims notes, beneficiary records and broker-of-record documentation. The hardening checklist follows the same five steps as the mortgage side, with one structural difference worth planning around.
Insurance platforms more often hold linked carrier credentials, and Applied Epic rating-engine integrations create lateral exposure. A compromised agent account can pull rate quotes at scale or attempt a fraudulent broker-of-record letter.
Fusion Computing monitors that with the same Microsoft Defender for Business signal plus a behavioural rule: alert on anomalous rating-request volume from one agent account. Role permissions map to RIBO licence level. The Insurance Brokers Association of Ontario offers continuing education covering cyber-readiness.
The FSRA examiners did not ask what security tools we had bought. They asked for the access-review log, the tabletop after-action report and the vendor-review folder. Fusion Computing built the runbook that produced those artifacts, and that is what made the attestation defensible.
FIELD NOTE FROM MIKE.
At an 18-agent Mississauga insurance brokerage in Q1 2026, my first finding was a missing offboarding runbook rather than a missing tool. Three former agents still held live Applied Epic credentials six to fourteen months after their last day, none with MFA enrolled. The fix took 90 minutes.
The broker-of-record / principal-broker attestation: what you are signing
Ontario puts a named individual on the hook. That is the principal broker under the Mortgage Brokerages, Lenders and Administrators Act, 2006, or under the Registered Insurance Brokers Act. The attestation covers policies, supervision and IT risk posture.
The attestation is annual. The evidence a regulator asks for is point-in-time. A brokerage that drafts policies on attestation day and lets them age 11 months fails the spirit of the regime.
The question that catches brokerages is the third-party one. A documented process for evaluating cloud vendors means a checklist on file and signed reviews for Microsoft 365, the BMS and the backup platform. In my experience, pointing at a vendor’s SOC 2 attestation never discharges it.
ORIGINAL DATA, FUSION COMPUTING BENCHMARK.
Across our 2025 and 2026 Ontario brokerage engagements we measured one pattern every time. Brokerages holding three artifacts, a risk register dated inside 12 months, an access-review log signed inside the quarter, and a tabletop after-action report, cleared the attestation with no follow-up. The rest drew an evidence request running 30 to 45 days.
FINTRAC and cyber: where the two regimes overlap, where you double-report
The overlap with cyber is the suspicious-transaction lens. A ransomware event against an Ontario brokerage can produce a reportable signature: a cancelled wire, an unauthorized payment instruction, a fraudulent broker-of-record letter. The FINTRAC report then travels beside the FSRA notification.
Know the ranges before quoting a decade-old figure. The Administrative Monetary Penalties Regulations were amended in force March 26, 2026. A minor violation now carries CA$1 to CA$40,000, a serious one up to CA$4,000,000 and a very serious one up to CA$20,000,000. Summaries citing CA$250,000 no longer match the instrument.
My runbook puts a decision branch at step 5. If the incident carries a financial-crime element, the IT lead brings in the named compliance officer, who works FINTRAC on its own timetable. Brokerages that merge the two streams file late with one agency.
The 90-day rollout: inventory, policy, IT controls, tabletop, notification SOP, renewal calendar
MBRCC and RIBO both expect a brokerage to operationalize a control set rather than buy one. My path compresses into 90 days. The IT work takes 24 to 32 hours, and governance fills the rest.
- Days 1-10, asset inventory and risk register. Catalogue every device, account and BMS integration, then date and sign the register.
- Days 11-20, governance policies. Draft acceptable use, AI use for insurance brokerages, access control and incident response. Output: 4 to 6 policy PDFs.
- Days 21-45, Microsoft 365 Business Premium hardening. Enable MFA everywhere, configure conditional access and deploy Defender for Business plus anti-phishing.
- Days 46-55, credential review. Rotate lender or carrier credentials, audit role assignments and retire ex-agent accounts.
- Days 56-70, backup and recovery. Deploy a third-party Microsoft 365 backup platform, document RPO and RTO, and run the first restore test.
- Days 71-80, tabletop exercise. Run a half-day scenario against the BMS or the principal broker’s mailbox, walking the SOP end to end.
- Days 81-90, training and the renewal calendar. Roll out awareness training, then diarize the quarterly access reviews, annual tabletop and attestation cycle.
The cost model for a 12-agent brokerage lands near CA$32 per user per month. Microsoft 365 Business Premium runs CA$26.40 per user, and third-party backup adds CA$4 to CA$6. Add a one-time CA$5,000 to CA$9,000 configuration engagement.
FIELD NOTE FROM MIKE.
Days 71-80 are the ones brokerages want to skip. Every Ontario tabletop I have run surfaced a gap the risk register missed, usually who signs the FSRA notification when the principal broker is on vacation. A half day now beats a 45-day evidence request later.
Want the 90-day rollout run for your brokerage? Talk to Fusion Computing →
Mortgage vs insurance: the difference in what you file, plus 6 things brokerages get wrong
The controls are shared. The filing tree is not. A mortgage brokerage files the FSRA notification, with FINTRAC duties alongside. An insurance brokerage files the same notification, layers RIBO conduct expectations on licensed activities, and reaches FINTRAC only on the life side. Both report to the Privacy Commissioner on the harm test.
Do
- Write down the materiality determination, with the time and the name of who made it. That timestamp is what FSRA measures 72 hours against.
- Keep the evidence ledger fresh. A risk register dated 14 months ago gets flagged even when current.
- Tie the BMS account lifecycle to the HR record. The credential that survives a departure turns up in the forensics.
Don’t
- Do not use a consumer free-tier AI assistant for client work in an insurance brokerage. RIBO pillar 4 makes residency a hard question.
- Do not treat a vendor’s SOC 2 attestation as your third-party review. MBRCC Principle 4 expects a brokerage-side one.
- Do not skip MFA on the BMS because Microsoft 365 has it. That gap is how lender-portal compromises start.
Bottom line
FSRA’s IT Risk Management Guidance, the four MBRCC principles, RIBO’s 2025 AI pillars and FINTRAC’s PCMLTFA duties form one expectation set. A 12-agent Ontario brokerage that walks my 90-day rollout ends with a defensible attestation and a schedule that keeps it fresh.
Further reading and primary sources
- FSRA IT Risk Management Guidance (GR0016INT).
- MBRCC Principles for Cybersecurity Preparedness (PDF).
- PIPEDA, Justice Canada consolidation.
- CCCS Baseline Cyber Security Controls.
HOW THIS GUIDANCE WAS ASSEMBLED.
This draws on anonymized client data from Fusion Computing’s 2025 and 2026 Ontario brokerage engagements, an FC internal benchmark of 90-day cyber-hygiene sprints, and first-person field observation from my practice since 2012.
Frequently Asked Questions
How many cybersecurity principles does the MBRCC publish for mortgage brokerages?
Four: responsibility and resourcing, identification and prevention of risks, incident monitoring and response, and third-party management. Nine is the number of working IT controls my decomposition produces from those four, and that is where the nine-principle claim comes from. FSRA adopted the four-principle document through guidance MB0048INF.
Does FSRA’s IT Risk Management Guidance apply to both mortgage and insurance brokerages?
Yes. GR0016INT binds every FSRA-regulated entity from April 1, 2024. RIBO stays the licensee-facing channel on insurance conduct, but the IT Risk Incident Notification Form applies on both sides.
When does the 72-hour FSRA notification clock actually start?
At the materiality determination, not at detection. Practice 7 asks for notification as soon as is reasonable, normally within 72 hours or sooner, after the entity determines an incident is material. My SOP puts a 15-minute triage clock in front and records who made the call.
What are RIBO’s four pillars under the May 2025 Responsible AI Use guidance?
Competency and accountability, client interest and suitability, transparency and human oversight, and privacy and data protection. Published May 29, 2025, it reaches any Ontario-licensed insurance broker using AI in licensed activities. The controls are an approval workflow, a client disclosure and a vendor review.
How much does the security stack cost for a 12-agent Ontario brokerage in 2026?
Near CA$32 per user per month: Microsoft 365 Business Premium at CA$26.40 per user, plus third-party backup at CA$4 to CA$6. Add a one-time CA$5,000 to CA$9,000 configuration engagement to reach a defensible posture inside 90 days.
Are mortgage brokers and insurance brokers reporting entities under FINTRAC?
Mortgage brokers, lenders and administrators are, and so are life insurance brokers. Property and casualty brokers generally are not. Penalty ranges amended in force March 26, 2026 now reach CA$4,000,000 for a serious violation and CA$20,000,000 for a very serious one.
Does a Canada-region Microsoft 365 tenant eliminate CLOUD Act exposure?
It reduces practical exposure without eliminating it, because Microsoft Corporation is a US-incorporated parent subject to US legal process. The mitigations are the Microsoft Customer Agreement commitments, in-region storage in Canada Central and Canada East, and a documented review of the residual risk.
What evidence does FSRA actually look at during a supervisory examination?
Freshness rather than existence. Examiners ask for a risk register dated inside 12 months, last quarter’s access-review log, the most recent tabletop after-action report, training completions and signed vendor reviews. A thin toolset with a complete ledger beats expensive tools with no artifacts.
FINANCIAL-SERVICES BROKERAGE DEEP DIVES (2026 CLUSTER)
- FSRA IT Risk Incident Notification SOP.
- the annotated MBRCC principles guide for Ontario mortgage brokerages.
- RIBO Responsible AI Use policy template.
- FSRA mortgage brokerage penalties, and what enforcement teaches.
- the Filogix and Velocity account-hardening guide.
- AI for Ontario insurance brokerages.
Related Resources
- Cybersecurity services for Canadian businesses.
- PIPEDA compliance for Canadian small business.
- AI for Canadian law firms, an LSO-aligned deployment guide.
- AI for Canadian accounting firms.
Reviewed by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited.

